Impact
The vulnerability is a use‑after‑free flaw in the Windows DHCP Server that leads to remote code execution when an authorized attacker succeeds in exploiting the defect. The flaw allows untrusted code to run with the privileges of the DHCP service, giving the attacker the ability to take full control of the affected host. Because the attack requires only that the attacker be able to send packets to the DHCP server from the same subnet, it can be carried out against any host running the vulnerable service on a local network.
Affected Systems
Microsoft Windows 10 versions 1607 and 1809, and Windows Server 2012 through 2025 including Server Core installations are affected. The vulnerability is present in the DHCP service component distributed with these operating systems, so any machine that has the service enabled and has not applied the Microsoft update for this issue is at risk.
Risk and Exploitability
The CVSS score of 8 reflects a high severity, indicating that successful exploitation would give an attacker full control over the DHCP server host. While no EPSS score is published, the absence of an EPSS rating does not imply the flaw is benign; it simply indicates that no publicly reported exploitation has yet been observed, yet the vulnerability still poses a serious threat. The KEV status shows this issue is not listed in CISA’s Known Exploited Vulnerabilities catalog, but the high CVSS combined with the fact that an attacker only needs to send crafted packets from the same local subnet makes exploitation likely in environments where such network proximity is possible. Since the flaw exploits an authorized network attacker, typical protective measures such as network segmentation, strict DHCP traffic filtering, and disabling the DHCP role when unnecessary can effectively mitigate the risk.
OpenCVE Enrichment